Anyone looking at our spambot data will notice that Rustock is again back among the spamming botnet leaders, despite being hampered for a time following the McColo takedown last November. Since then it has been a roller coaster ride for Rustock but it is now gaining momentum. Rustock spamming activity is currently responsible for 35% of spam received in our spam traps. Given its prominence, we thought it would be timely to revisit this beast to highlight some of its characteristics.
Rustock is one of the fastest spambots we have observed (~25,000 spam per hour/bot) and employs a complex rootkit capability enabling it to stay hidden on the computer. Its perhaps no surprise that this botnet is taking the lead again amongst the major spammers.